| EV-BASE-01 | Source/OpenAPI parity | make generate-check | No diff or stale generated artifact | M0/C01 | every candidate |
| EV-UNIT-01 | Go package behavior | make test | All packages pass on pinned source | M0–M9 | every candidate |
| EV-ACC-01 | Contract and acceptance suite | make acceptance | All acceptance assertions pass | M1–M9 | every candidate |
| EV-HELM-01 | Rendered chart safety | make helm-lint | Chart renders and policy checks pass for exact values | M6/M9 | every chart/config change |
| EV-LIFE-01 | All-eight hermetic lifecycle | make e2e-hermetic | Complete journey and per-step readback pass from empty state | M3 | every candidate |
| EV-LIFE-02 | Target-cluster lifecycle | guarded cluster procedure | Real Knative/registry lifecycle passes against named environment | M3/M9 | every candidate/environment |
| EV-FAIL-01 | Crash and ambiguity matrix | fault-injection suite | No duplicate effects; expected UNKNOWN/reconciliation states persist | M4 | every effect/payment change |
| EV-PAY-01 | Bounded real USDC trace | guarded real-spend procedure | Exact Base evidence reconciles to action, receipt, and ledger under cap | M5/M9 | before pilot and each payment change |
| EV-SEC-01 | Runtime and tenant security | target-cluster security suite | Isolation, CNI policy, RBAC, secrets, provenance, and resource bounds pass | M6/M9 | every runtime/policy change |
| EV-RESTORE-01 | Real isolated restore | VolumeSnapshot restore drill | Replacement PVC restores complete canonical state within adopted RPO/RTO | M8/M9 | before pilot; recurring during operation |
| EV-OPS-01 | Alerts and outage behavior | injected dependency/outage drill | Expected alert, containment, recovery, and evidence are recorded | M8/M9 | before pilot and each alert/runbook change |
| EV-REL-01 | Exact release rehearsal | release rehearsal packet | Install/upgrade/fail/rollback/restore/rotate/freeze pass on exact digests | M9/G-PROD | each candidate |
| EV-PILOT-01 | Paid operated-product proof | bounded pilot evidence packet | SLO, traces, reconciliation, cost, support, repeat use, and incidents reviewed | M10/G-SINGLE | pilot close |
| EV-COMMIT-01 | Deterministic block, Merkle, and CID vectors | cross-run golden vector suite | Identical eligible records produce identical ordered leaves, root, envelope bytes, and expected CID; mutation, omission, duplication, and reordering are detected | M1/M2/M7 | every evidence-format change |
| EV-COMMIT-02 | IPFS round trip and availability | publish exact canary bytes; retrieve through independent endpoint/pin | Retrieved bytes match expected CID and reproduce the Merkle root through at least two availability paths | M7/G-IPFS | every release and recurring operation |
| EV-COMMIT-03 | Optional Base anchor and reorg verification | separately authorized bounded anchor canary | Exact node/sequence/root/CID commitment reaches adopted finality; reorg cannot rewrite canonical or sealed history | G-COMMIT-BASE | before activation and each anchor change |
| EV-COMMIT-04 | Crash and ambiguity recovery | fault injection at cutoff, serialize, seal, publish, CID-persist, and readback boundaries | Recovery resumes identical bytes and one logical node/sequence without omission, duplicate publication identity, or conflicting root | M7 | every publication-state change |
| EV-COMMIT-05 | Independent evidence verification | standalone verifier starts from CID and retrieved bytes without cynderd access | Verifier validates schema/linkage, reconstructs leaves/proofs, and reproduces the expected root while exposing coverage boundaries | M7/M9/M10 | every release and pilot window |
| EV-COMMIT-PRIVACY | Public evidence privacy boundary | forbidden-field fixture corpus plus serialized-object scan | No secrets, authorizations, private inputs/outputs, credentials, or prohibited customer metadata enter IPFS objects | M7/G-IPFS | every projection/schema change |
| EV-WALLET-01 | Customer signer contract and replay domain | cross-language EIP-191 vectors plus EOA/contract-wallet negative fixtures | Only the exact supported EOA, origin, method, route, action, idempotency key, and digest verify; ERC-1271 fails explicitly | M1/G-WALLET-CONTRACT | every signing-contract change |
| EV-WALLET-02 | Node role and custody separation | manifest/runtime/custody inventory plus key/account collision tests | Evidence, anchor, payee/treasury, admin, pauser, refund, and customer roles are independently bound; no treasury/admin key is in cynderd | M5/G-WALLET-CONTRACT | every role/config/release change |
| EV-WALLET-03 | Rotation, revocation, compromise, and restore | planned and emergency evidence/anchor/payee/admin rotation drills plus stale-snapshot recovery | History remains verifiable; new authority starts at explicit boundary; old restore cannot fork node/sequence | M5/M8/G-WALLET-CONTRACT | before production and every custody change |
| EV-USDC-CONTRACT-01 | Pinned Base USDC identity | chain/address/ABI/EIP-712 domain/proxy implementation/runtime-code and event verification | Configured native Base USDC is exact and drift is detected before paid readiness | M5/G-WALLET-CONTRACT | startup, release, and dependency change |
| EV-USDC-CONTRACT-02 | EIP-3009 settlement truth | forked-chain unused/settled/duplicate/expired/malformed/reorg fixtures | Facilitator response cannot override canonical authorization, Transfer, receipt, block, payer, payee, amount, and action evidence | M5/G-WALLET-CONTRACT | every payment/reconciliation change |
| EV-ANCHOR-CONTRACT-01 | Anchor ABI/state/event/access invariants | Solidity unit/fuzz/invariant tests plus Go/Solidity anchor-ID vectors | Unauthorized, replayed, skipped, stale-predecessor, duplicate, and conflicting anchors fail; pause/rotation preserve head | G-COMMIT-BASE | every contract change |
| EV-ANCHOR-CONTRACT-02 | Immutable deployment identity | verified source/bytecode/compiler/constructor/ABI/runtime-code/deployment transaction readback | Signed deployment manifest reproduces exact immutable Base deployment identity | G-COMMIT-BASE | every deployment |
| EV-ANCHOR-TX-01 | Bounded anchor transaction lifecycle | Sepolia canary with signer policy, nonce/replacement, fee caps, receipt loss, reorg, RPC outage, and backlog recovery | One immutable intent per sequence reaches configured finality or halts without root/sequence mutation; IPFS/customer execution continues | G-COMMIT-BASE | before mainnet and every submitter/finality change |
| EV-TREASURY-01 | Payment and refund reconciliation | payer→original-payee→treasury/refund chain and ledger reconciliation | Zero unexplained variance; refunds return only to original payer under dual approval and stable intent identity | M5/G-WALLET-CONTRACT/M10 | daily and every refund |